CVE-2020-8616
bind9 - security update
8.6
HIGH
CVSS 3.1
EPSS 10.6%
描述
A malicious actor who intentionally exploits this lack of effective limitation on the number of fetches performed when processing referrals can, through the use of specially crafted referrals, cause a recursing server to issue a very large number of fetches in an attempt to process the referral. This has at least two potential effects: The performance of the recursing server can potentially be degraded by the additional work required to perform these fetches, and The attacker can exploit this behavior to use the recursing server as a reflector in a reflection attack with a high amplification factor.
如何修補 CVE-2020-8616
要修補 CVE-2020-8616,請將受影響套件升級到下列已修補版本。
- —升級至 9.14.12-r0 或更新版本
CVE-2020-8616 正在被利用嗎?
中等 — EPSS 為 10.6%,可持續追蹤但非最高優先。
受影響套件(1)
- >= 9.0.0, < 9.14.12-r0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.6 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |